PT-2026-69989 · Ping Identity · Pingfederate

·

CVE-2025-32736

·

Published

2026-08-10

·

Updated

2026-08-28

CVSS v4.0

6.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions PingFederate versions prior to 13.1
Description Cross-Site Request Forgery (CSRF) weaknesses in the Administrative Console may allow actors to perform unauthorized actions. This occurs when administrators with active sessions are triggered to click specially-crafted links. CSRF is a flaw that allows an attacker to induce a user to perform actions they did not intend to do on a different website.
Recommendations Update to version 13.1 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-32736

Affected Products

Pingfederate